{"id":"CVE-2026-94287","published":"2026-09-28T09:17:08.577","lastModified":"2026-09-29T21:32:59.833","description":"A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.","cvssScore":5.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwes":["CWE-1050"],"vendors":[],"products":[],"references":[{"url":"https://gitlab.freedesktop.org/xorg/lib/libxpm/-/merge_requests/32/diffs?commit_id=3a68f818b1628d7ad96245b0f4d15a32a015b0ab","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}